CVE-2021-35500

The Data Virtualization Server component of TIBCO Software Inc.'s TIBCO Data Virtualization, TIBCO Data Virtualization, TIBCO Data Virtualization, and TIBCO Data Virtualization for AWS Marketplace contains a difficult to exploit vulnerability that allows a low privileged attacker with local access to download arbitrary files outside of the scope of the user's permissions on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO Data Virtualization: versions 8.3.0 and below, TIBCO Data Virtualization: version 8.4.0, TIBCO Data Virtualization: version 8.5.0, and TIBCO Data Virtualization for AWS Marketplace: versions 8.5.0 and below.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:tibco:data_virtualization:*:*:*:*:*:*:*:*
cpe:2.3:a:tibco:data_virtualization:8.4.0:*:*:*:*:*:*:*
cpe:2.3:a:tibco:data_virtualization:8.5.0:*:*:*:*:*:*:*
cpe:2.3:a:tibco:data_virtualization_for_aws_marketplace:*:*:*:*:*:*:*:*

History

19 Jan 2022, 19:38

Type Values Removed Values Added
CPE cpe:2.3:a:tibco:data_virtualization:8.4.0:*:*:*:*:*:*:*
cpe:2.3:a:tibco:data_virtualization:*:*:*:*:*:*:*:*
cpe:2.3:a:tibco:data_virtualization:8.5.0:*:*:*:*:*:*:*
cpe:2.3:a:tibco:data_virtualization_for_aws_marketplace:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 2.1
v3 : 5.5
References (CONFIRM) https://www.tibco.com/support/advisories/2022/01/tibco-security-advisory-january-12-2022-tibco-data-virtualization-2021-35500 - (CONFIRM) https://www.tibco.com/support/advisories/2022/01/tibco-security-advisory-january-12-2022-tibco-data-virtualization-2021-35500 - Vendor Advisory
References (CONFIRM) https://www.tibco.com/services/support/advisories - (CONFIRM) https://www.tibco.com/services/support/advisories - Vendor Advisory
CWE NVD-CWE-noinfo
First Time Tibco data Virtualization
Tibco data Virtualization For Aws Marketplace
Tibco

12 Jan 2022, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-01-12 19:15

Updated : 2023-12-10 14:09


NVD link : CVE-2021-35500

Mitre link : CVE-2021-35500

CVE.ORG link : CVE-2021-35500


JSON object : View

Products Affected

tibco

  • data_virtualization_for_aws_marketplace
  • data_virtualization